Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Layer 2 person spoofing and impostor syndrome

Bea Hughes
November 22, 2017

Layer 2 person spoofing and impostor syndrome

For Bsides Wellington in New Zealand, November 2017

"Impostor syndrome, a concept describing individuals who are marked by an inability to internalize their accomplishments and a persistent fear of being exposed as a "fraud"."

Bea Hughes

November 22, 2017


  1. Layer 2 person spoofing and impostor syndrome % sudo ifconfig

    en0 ether 78:4f:43:69:1b:10 \ && ifconfig en0 | head -3 en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500 ether 78:4f:43:69:1b:10 inet netmask 0xfffffc00 broadcast Thanks hotspot.nzwireless.co.nz @benjammingh for BsidesNZ 1
  2. Who's this clown? (1/2) 2 • Security Engineer at Stripe.

    • Infrastructure security at Etsy. • Opera5ons engineer at Puppet. • Two 5me sponsor of Wrong Island Con. 2 h$ps:/ /twi$er.com/skullmandible/status/411281851131523072 @benjammingh for BsidesNZ 2
  3. Who's this whingeing pom? (2/2) • Knows how to pronounce

    "router". • Is delighted to be back here enjoying the 300/400ms latency on everything. • Has had his Instagramme stuck giving him NZ ads for the past 3 months. (if you know how to fix this, please help me!) @benjammingh for BsidesNZ 3
  4. vulnerability |vʌln(ə)rəˈbɪlɪ4| noun (plural vulnerabili*es) [mass noun] the quality or

    state of being exposed to the possibility of being a5acked or harmed, either physically or emo:onally: conserva:on authori:es have realized the vulnerability of the local popula:on @benjammingh for BsidesNZ 9
  5. the quality or state of being exposed to the possibility

    of being a5acked or harmed, either physically or emo$onally @benjammingh for BsidesNZ 10
  6. So if you're looking for 0-day, you may be in

    the wrong room. @benjammingh for BsidesNZ 11
  7. Impostor syndrome is when high- achieving individuals are marked by

    an inability to internalise their accomplishments & a persistent fear of being exposed as a "fraud" — clinical psychologists Dr. Pauline R. Clance & Suzanne A. Imes @benjammingh for BsidesNZ 13
  8. "Am I even qualified to give this talk?" — Me,

    earlier today, proving that I probably am. @benjammingh for BsidesNZ 14
  9. "I am going to be discovered and fired..." — Me,

    then. @benjammingh for BsidesNZ 19
  10. Impostor syndrome can be a sign that you're about to

    learn awesome things. @benjammingh for BsidesNZ 32
  11. It can be a sign you have a lot of

    knowledge to share too! @benjammingh for BsidesNZ 33
  12. Straw poll How many people have you heard of ge3ng

    fired due to knowing nothing? How many people have you heard of having impostor syndrome? @benjammingh for BsidesNZ 34
  13. Infosec problems (including but not limited to) • Has a&ackers.

    Coders have bugs, ops people have well the world. There are real humans a&acking you trying to break your shit.* • There is very clear win/lose stakes. • Especially in the con scene, a lot of posturing. • DefCon sCll exists (; * Assume blue team here, I know... @benjammingh for BsidesNZ 38
  14. ...which leads to • people not showing their vulnerabili3es (not

    that kind). • people not admi:ng they don't know something out of fear. • people burning out and leaving the industry. • Infosec not being the most diverse and inclusive industry. @benjammingh for BsidesNZ 39
  15. "well don't think of yourself as an imposter, think of

    yourself as not a psychopath." — Sco& Roberts @benjammingh for BsidesNZ 40
  16. "One of the best things I've done for myself lately:

    created a doc where I copy-paste compliments I've go<en. Great for low days. Try it." — Molly Clare @benjammingh for BsidesNZ 41
  17. "For passphrases, make them something posi2ve and encouraging, so every

    2me you have to type them in, you feel a li:le be:er about the world." — paraphrased from an Anonymous Canadian @benjammingh for BsidesNZ 42
  18. Tip for praise: Don't personalize. For the same reason you

    wouldn't say "You're a dumbass," don't just say "You're a genius." — @candor 5 5 Blameless praise! from Slack's great ar5cle on giving feedback @benjammingh for BsidesNZ 52
  19. Let's hope I'm on track for 2me! • be understand

    to people, this is hard. • be kind to yourself, even if you're a jerk like me. • seek help if you can (friends, therapists, coworkers) @benjammingh for BsidesNZ 56
  20. This affects people differently • Confidence sadly o.en comes with

    privilege. • As does arrogance. @benjammingh for BsidesNZ 57
  21. Mess of links that will be useful when I tweet

    the URL to this slidedeck • Impostor Syndrome in DFIR - Sco5 Roberts fantas9c piece on the topic. • Allowed To Apply - blog on telling yourself you can do this. • How to get a promo9on • Blue Hackers - site on mental health in the tech community and how to help. @benjammingh for BsidesNZ 58
  22. If this sounds like an environment you'd like to work

    in, come talk to me about Jobs at Stripe @benjammingh for BsidesNZ 59
  23. Ta • My blog post on the subject • Fax:

    +1 (415) 484-7239 • Twidder: @benjammingh • SpeakerDeck: speakerdeck.com/barnbarn @benjammingh for BsidesNZ 60